Everything you say to your Echo will be sent to Amazon starting on March 28
arstechnica.com
arstechnica.com
All these smart speakers can turn that on anytime processing and storing such a vast amount of data becomes viable. Not surprised. I don’t use any of these smart devices for exactly this reason.
I don’t need smart XYZ appliances that connect to the internet. After working a decade in the industry, I’ve seen enough of what these companies do with user data. No thank you.
Also, I don’t speak English at home. So that’s a hedge for now I guess.
The same is true for smart phones, yet almost nobody has an issue with those.
Not only could they listen at any time (albeit with lower quality), I put extremely personal information into my phone via the screen keyboard all the time. How is trusting the manufacturer to not transfer that information any more reasonable than trusting Amazon to not spy on me when they say they don't?
Probably because phone manufacturers have historically not done things as bad as Amazon has privacy-wise.
But you're right. They could.
Let me just be the first to say I absolutely have an issue with smartphones.
(edit: Of course, I could very well count in the 'almost nobody' category, but the same might well be true in general for people concerned about smart devices.)
But I'm also a pragmatist.
In my opinion Apple, while not even approaching being "perfect", are most likely to be the least worst of all practical options. 5 or 10 years back, I would have ranked Google's Pixel phones in 2nd, but not so much these days, if they're still 2nd they're a long long way back from 1st and only second because every other choice is so so bad. I used to buy Samsung phones back in the Galaxy S2 up to Galaxy S6 era, but they did so many bad-for-security things I no longer trust them with any of my data.
I don't trust any of the Chinese brand at all. Although I do have a few super inexpensive Chinese Android tablets that get used on a non internet connected subnet as home automation controllers. Even if they do manage to phone home, the only sensitive data they have is the private subnet wifi password and the always-on VPN endpoint through the router. I like to think (but cannot prove) that Chinese manufacturing hasn't managed to plant working backdoors in every iPhone they build, and that if they have targetted supply chain attacks for individual or small batches of devices that I'm not interesting enough to burn one of those on. I do sometimes wonder whether Jamal Khashoggi thought that too though...
I've "settled" with the level of security I believe my iPhone gives me. Partly because I long ago made peace with the fact that if a nation state security agency even became "interested" in my, I've already lost the game. I've given up trying to protect myself against the NSA or Mossad or the MSS or the FSB, or even "second tier" security agencies like my local ASIS. I do what I can to make it hard for adversaries like organised crime, scammers, script kiddies, and surveillance capitalists, and I'd like to think I've done enough that law enforcement (short of ASIS) probably can't access data on my devices via technical means (while knowing full well they have the capability to ruin my life if I refuse to hand over password and decryption keys).
Degoogled Android like Graphene is way better for privacy as long as you are careful with the apps you install.
I went with him to an appointment. As a condition of checking in to see his doctor, on a silly tablet at the office, he had to sign away his HIPAA rights for them to sell his charts, along with his identity information, to advertisers or any other third parties. I was beside myself.
Wasn’t long afterward before he started seeing insultingly specific (but medically incorrect) prescription drug ads, almost exclusively, on his TV service.
As with QR codes in restaurants, reception tablets with NDA boilerplate, or electronic security scanners, declining to use an electronic device can lead to the magical appearance of a manual alternative, where lines of text on paper can be crossed out manually before signing and taking a photo for your records.
This is because the consent (of 99% who will not decline) is only valid if the 1% who choose to decline can actually do so. If everyone is forced and it's literally impossible to decline consent, then none of it is consent, and they may as well omit the text and do whatever they want anyway. The act of asking consent for ridiculous terms is actually quite positive, if one ignores the implied pressure of a silicon wrapping.
I’m actually fully on-board with everything in this thread. This should obviously be taken more seriously than it is.
Well, they can always refuse service, but now their refusal is linked specifically to the crossed-out lines, an action that can lead to various paths. If the deleted lines are known by them to be overreaching, they are economically better off to provide service and earn revenue, instead of losing 100% of revenue and appointment slot to a minor technicality worth much less.
Healthcare providers or institutions may require a patient to sign certain forms related to the treatment or payment process (like consent forms for treatment or payment authorization), but these forms cannot waive the patient's fundamental rights under HIPAA. If a patient feels coerced into signing anything, they can refuse or ask for clarification before signing. If they don't want to sign, it shouldn't prevent them from receiving care, although certain administrative procedures (like billing or insurance claims) might be impacted.[1] https://www.apple.com/legal/privacy/data/en/ask-siri-dictati...
"Here’s how it works: When you turn on Do Not Send Voice Recordings and say your chosen wake word, an on-device algorithm will process and transcribe your request to Alexa from audio into text. The text is encrypted and sent to Amazon’s secure cloud where we can fulfill your interaction. After processing, the audio of your request is deleted."
So they transcribed the voice and sent the text to the cloud. Surprising that needs to go to allow GenAI to work?
Here's the email they sent: https://imgur.com/ZGPBwgZ
[1] https://www.amazon.com/b?ie=UTF8&node=23727313011#:~:text=He...
Like I think it would be possible to have text/voice/object recognition work on the photos you send in an end-to-end encrypted chat app, described out-of-band and used for ... purposes.
<encrypted data stream>
<"spoken keyword: starbucks">
<"picture: LG washing machine">
<"picture: donald trump">
<"text: prescription xanax">Echo can work offline for control of Zigbee devices connected to Echo (non-Dot) Gen4, which is a Zigbee hub with US firmware. Voice commands such as "Turn Porch Light On" can be processed locally on Echo and executed immediately, without an internet connection, https://news.ycombinator.com/item?id=43368008
If an Alexa customer is using this offline functionality today, with no interest in GenAI or other online features, how can Amazon remove it?
Just like some people need to touch a hot stove to learn they need to be careful some people will just refuse to accept anything bad is happening to them until they see it with their own eyes and surveillance capitalism exploits that by keeping the harms so removed from the collection of private data that most people will never accept the connection even after they're told about what's happening.
Eager to replace my cheap Echo devices with more expensive privacy friendly options.
Another question: anyone aware of community custom firmware efforts? I know early gen devices had some exploits but it never resulted to much last I checked.
Voice detection is pretty good, especially on the Voice, even from across a room. Not 100% (especially with higher pitched voices), but definitely high and usable. The main downside is the fact that you either need to host a local LLM, which isn't cheap, or predefine all phrases you want.
I'd implement the actual smarts myself, I just want the STT/TTS interface sorted.
https://github.com/rhasspy/wyoming
This subproject looks interesting too
so in conclusion: nope.
It is literally impossible to transcribe voice, especially if you whisper. There's no way to model the language, it's too large - amanzon has many computers. Your computer is like a tortoise, it can't do text-to-speech. There's no way you can get any of this to use the Web, Dav... er, Cal. Trying to do this would be like trying to torch a python with your bare metal hands.
that is:
baremetal pytorch https://en.wikipedia.org/wiki/PyTorch
WebDAV/CalDAV https://en.wikipedia.org/wiki/CalDAV
tortoise-tts https://github.com/neonbjb/tortoise-tts/issues
LLM/Large Language Model https://lmstudio.ai/
whisper https://github.com/openai/whisper/
in reverse orderoh also i have "FUTO Keyboard" on android, and it uses a local LLM (you can pick three "sizes" depending on your device specs and desired battery life) to transcribe my voice. It's pretty good for non-technical conversations, but it starts to trip up if one's jargon pronunciation is close to other words - "Tea Sip, I pee" sort of confounding errors.
Setting a timer, calling someone, turning on a light.
But is local CPU Speech to Text really a dead end?
Even in the voice-cloning TTS you have to deliberately spell things to be pronounced correctly.
so it comes down to "guessing the context" for a computer, which is something that LLMs can do fairly well, and raspberry pi can run small LLM, so who knows. Sentiment analysis is one thing, i'd probably mess with prompting an llm to "correct the grammar" and see what words change - or even "change words for synonyms that can't be misconstrued by the TTS engine, unless the tone of the phrase or passage changes dramatically, in which case, phonetically spell the word in question"
but i only think to do this because LLMs exist. if you had asked me 15 years ago how to automate "pronunciation" of english i'd have said "if IBM and AT&T and Apple can't figure it out..."
Models are killing it but that is just an "ollama run" command away.
See for instance [0], which is just starting to appear in commercial parts.
This is continuing; pretty much every low cost SoC maker is racing to build and extend ML optimizations.
0. https://www.synopsys.com/blogs/chip-design/best-edge-ai-proc...
It is not.
You could not pay the average person to run a local LLM instead of just relying on Siri/Alexa/Google Assistant/whatever is built into the apps and hardware they use every day.
You could sell these to HN commenters who will play with it for a week and then put it in the cupboard to gather dust next to their Raspberry Pis.
It didn't have a wakeword, you'd hit the arcade button (which had a dim color when inactive), it'd pulse white or blue, and then the assistant voice would ask whatever google assistants ask, and the light would change red, and you could ask your question, the light would pulse, and a second or two later, the assistant would talk, replying to your request or whtaever.
now, i am working from memory, so it may have been amazon services, but i am unsure if they allow third party access, and it may have immediately waited for your question when you pushed the button. I don't remember.
If i can find one of my boxes, in a closet gathering dust next to the rest of my rpi, i'll at least try to get the model/name of the microphone array hat, because i think that's the part that will make a DIY voice assistant work rather than be a curiosity.
mine stopped working after a few weeks, and i couldn't ever figure out why. I think maybe google or whatever wanted money for API usage, or they changed the rules of how firebase worked... but the hardware still works, it just doesn't "wake up" when you push the button. the logs show the button push, etc.
anyhow, i got the last two at target like 5(?) years ago, for $10 each. i think it was called "AIY Voice Kit"
Ramble follows, feel free to ignore
the AIY kits were "on clearance" when i got them, and i haven't seen similar since. But the issue isn't that people don't want to "own their data" and "DIY" - but think of all of the things you need to know how to do, to set up that device i spoke of. Linux shell. Wifi / networking. Electronics.
Figuring out the moving target of google infra services. Let's pause here; if this part is removed, we get a bunch more - running things in docker, or compiling from source, or python venvs. You have to have enough compute just laying around to do the processing of voice and tts, you still have to "hook up" all of the piping to something that can actually "do work" based on "plain english commands"
how many people on HN could set up a voice assistant without any assistance? With the archlinux wiki and stack and copilot that number might grow a magnitude or two. I do mean the full stack, but COTS hardware.
it's marginally easier these days than it was when i bought that AIY Voice Kit - transcription and TTS are downright magical, and built upon at least a decade and a half of prior art; I don't think tortoise-tts has much in common with the TI-49/A or Apple powerPC era text to speech. I don't think whisper has much in common with Dragon Naturally Speaking, or the powerPC era "short commands" that you could use with applescript.
If some startup wants to try and light investor money on fire a little slower, it should be possible to design and build a "home assistant" device that's like a 100 TOPS tegra or functionally equivalent running linux as a "base station" and remote or satellite transceivers that have the wakewords and whatnot on them. Think like a cordless phone. Obviously to build a moat we'd use some arbitrary wireless protocol, if not proprietary. nah, it should be wifi, maybe even as part of a "home mesh wifi" system or something?
you're still gunna lose your ass trying to make something people want at a decent price.
I can use my HA Voice with a Local LLM, OpenAI, or Home Assistant cloud. Similar I can swap out TTS and STT with local versions if I want.
¹) however, their focus is less on home automation, more on personal information management, AFAIK.
- Jeff Bezos
Unplug those things already. Alexa devices are spyware.
Otherwise I can't see how this isn't blatantly violating 2-party consent laws in every state that has them, as Amazon can't reasonably claim they've received affirmative consent from every guest in their customers' homes...
According to Verge [1], this was only available on 3 devices: Echo Dot (4th Gen), Echo Show 10, and Echo Show 15 – and only for customers in the U.S. with devices set to English.
So unless you have any of these devices, and are in the US, with English as the main language, ignore the news. This is not going to affect you. If you do, then your device commands NOT everything you say within reach of the Echo device will be processed remotely.
I'm happy to be corrected here, but this looks like it's no news dressed as Nasty-Tech-Oligarchs-Doing-More-Nasty-Things news.
[1] https://www.theverge.com/news/630049/amazon-echo-discontinue...
> Amazon is switching on local voice recognition processing, promising users of some of its latest Echo smart speakers and smart displays that they can have their Alexa commands avoid the cloud completely... taps into the retail giant's homegrown AZ1 Neural Edge chipset.. followed Google, Apple, and others in creating its own custom silicon. While the AZ1 may not have been able to power the whole Alexa experience, it was focused instead on specific voice recognition features.
(Echo 4 is one of the few Zigbee hub options with US firmware)
If Echo Zigbee devices will effectively be bricked from their current offline purpose and use cases, it could motivate attempts to re-purpose the hardware. Has nothing been learned from the recent Sonos debacle?
I have not done this verification myself. I assume that every device and every piece of software is collecting data on me. I take some steps to reduce it (uBlock Origin in my browser, PiHole on my phone, don't use a fucking Amazon Echo), but I've just come to accept that companies don't give a shit about privacy and will get to know as much as they can about me so they can try to sell me things.
This headline is one of those things where if you're caught off-guard and are surprised, you're terrifyingly naive. Be upset, sure, but don't be surprised.
Some years ago there were some news about some employees who were actually "executing" the comands spoken to Alexa.